← Latest papers
🔢 mathematics

A Compact Post-quantum Strong Designated Verifier Signature Scheme from Isogenies

This paper proposes a new compact, post-quantum strong designated verifier signature scheme based on (abelian) cryptographic group actions and isogenies, ensuring that only the designated verifier can confirm a signature's authenticity.

Original authors: Farzin Renan, Wendi Gao, Jason T. LeGrow

Published 2026-09-14
📖 5 min read🧠 Deep dive

Original authors: Farzin Renan, Wendi Gao, Jason T. LeGrow

Original paper licensed under CC BY 4.0 (http://creativecommons.org/licenses/by/4.0/). This is an AI-generated explanation of the paper below. It is not written or endorsed by the authors. For technical accuracy, refer to the original paper. Read full disclaimer

In the digital world, trust is usually a public affair. When you sign a document online, a digital signature acts as a seal that anyone with the right tools can verify. This transparency is the backbone of modern security, ensuring that a message truly came from its sender and has not been altered. However, there are situations where this public nature is a flaw rather than a feature. Imagine a private conversation between two people where one wants to prove their identity to the other, but must ensure that no third party can ever be convinced that the message came from them. If the recipient could prove the origin to a judge or a friend, the privacy of the exchange would be broken. This is the challenge of "designated verifier" signatures: creating a proof that is undeniable to the intended recipient but completely unconvincing to anyone else.

The difficulty deepens when we consider the future. The encryption methods that currently protect our data rely on mathematical problems that are hard for today's computers but could be solved easily by powerful quantum machines. As scientists race to build systems that can withstand these future threats, they are turning to a branch of mathematics involving the shapes of curves and the ways they can be transformed into one another. These transformations, known as isogenies, offer a new foundation for security that is believed to be safe from quantum attacks. The goal is to build a system that not only survives the quantum era but also preserves the delicate privacy of designated conversations.

A team of researchers has now introduced a new method for creating these private, quantum-safe signatures. They call their system CSI-SDVS, a scheme built on the properties of commutative supersingular isogenies. The core idea is to use the unique mathematical relationship between elliptic curves to create a signature that only the intended recipient can verify. In this system, the sender and the recipient each hold a secret key and a corresponding public key. When the sender wants to sign a message, they use their secret key and the recipient's public key to generate a unique code. The recipient can then use their own secret key to check if the code is valid. The brilliance of the design lies in its ability to simulate. The recipient can also use their secret key to generate a signature that looks exactly like one from the sender. Because the recipient can create a perfect fake, they cannot prove to a third party that a specific signature came from the sender rather than being created by themselves. This property, known as non-transferability, ensures that the conversation remains private even if the recipient tries to share the evidence.

The researchers demonstrated that their new scheme is not only secure against quantum computers but also highly efficient. In previous attempts to build similar systems, the digital keys and signatures were often enormous, requiring hundreds of kilobytes of data to store or transmit. This made them impractical for many real-world applications. The new design, however, is remarkably compact. Using a specific set of parameters known as CSIDH-512, the researchers achieved a system where the secret keys are 256 bits long, the public keys are 512 bits, and the signatures themselves are also just 512 bits. To put this in perspective, a standard digital signature in older systems might be the size of a small text file, whereas this new signature is roughly the size of a single line of text. This dramatic reduction in size makes the technology viable for use on devices with limited memory and bandwidth.

The team proved that their system meets all the rigorous security standards required for this type of cryptography. They showed that an attacker cannot forge a signature without the secret keys, and they proved that the identity of the signer remains hidden from anyone other than the designated verifier. These proofs rely on the assumption that solving certain mathematical problems related to the group actions of these curves is computationally impossible, even for a quantum computer. The researchers also explored a specific mathematical model to show that the security of their system could be tied to a slightly different, but equally hard, problem. This dual-layered approach strengthens the confidence in the system's robustness.

By combining the privacy of designated verification with the efficiency of isogeny-based cryptography, this work offers a practical solution for secure, private communication in a post-quantum world. It moves the field from theoretical possibilities to concrete, usable tools. The researchers have shown that it is possible to have a signature that is strong enough to be trusted by the recipient, yet weak enough to be denied to everyone else, all while keeping the data small enough to be used anywhere. This balance of privacy, security, and efficiency marks a significant step forward in preparing our digital infrastructure for the challenges of the future.

Drowning in papers in your field?

Get daily digests of the most novel papers matching your research keywords — with technical summaries, in your language.

Try Digest →